Article 01Data controller
The controller of personal data processed for its own purposes is 4Cyber s.r.o., Company ID: 22094458, with its registered office at Zelený pruh 95/97, Braník, 140 00 Prague 4.
For enquiries and to exercise your rights, contact us at info@4cyber.cz.
4Cyber s.r.o. acts as a controller when processing personal data for its own purposes, particularly to manage business relationships, issue invoices and respond to enquiries. When processing personal data of employees and other individuals on the customer’s documented instructions, it acts as a processor under a data processing agreement. The customer is the controller of that data and determines the purposes and means of processing.
Article 02Data we process
The scope of data depends on the service used and the platform settings. It may include:
- Identification and business data: first name, surname, company name, company registration number and VAT ID.
- Contact details: email, phone number and address.
- Account and training data: username, assigned courses, activity and results of tests, training and phishing simulations.
- Data uploaded by the customer: personal data contained in the customer’s documentation, courses or GRC evidence, where uploaded to the platform by the customer.
- Billing data: information required for payments and tax documents.
- Technical data: IP address, device type, browser, operational logs and cookies, depending on the features used and settings selected.
Article 03Purposes and legal bases for processing
The following overview concerns processing where 4Cyber s.r.o. acts as controller. Data concerning the customer’s employees that is processed on the customer’s instructions is governed by the data processing agreement and the legal basis determined by the customer.
| Purpose | Legal basis |
|---|---|
| Responding to business enquiries and communicating with the customer’s contact persons | Legitimate interest in responding to enquiries and managing business relationships. |
| Performing a contract entered into directly with a self-employed individual | Performance of a contract or steps prior to entering into it under Article 6(1)(b) GDPR. |
| Invoicing and keeping records required by law | Compliance with a legal obligation. |
| Protecting systems, resolving technical issues and protecting legal claims | Legitimate interest in secure operation and the protection of rights. |
| Newsletters based on consent | Consent under Article 6(1)(a) GDPR. |
| Optional analytics and marketing cookies | Consent, where required for their use. |
Data necessary to process an order and comply with legal obligations must be provided so that the service can be agreed and properly delivered. Providing data for newsletters and optional cookies is voluntary. We assess legitimate interests with regard to the rights and interests of the individuals concerned.
Article 04Data retention
We retain data only for as long as appropriate for the processing purpose:
- Business and contractual documentation for the duration of the contractual relationship and, generally, for a further 5 years to protect and exercise legal claims; in an ongoing dispute, for as long as necessary to resolve it.
- Accounting and tax records for the period required by applicable legislation.
- Enquiry data for as long as needed to respond and conduct subsequent business communication; longer retention requires a separate justification.
- Newsletter data until consent is withdrawn or the relevant processing purpose ends.
- Operational logs for as long as necessary to protect systems and resolve specific incidents.
- Customer data processed on the customer’s instructions for the agreed processing period and in accordance with the data processing agreement. On termination, return or deletion is governed by that agreement and statutory obligations.
Article 05Recipients of personal data
Data may be disclosed to authorised staff and providers of IT, hosting and accounting services to the extent necessary, and to public authorities where required by law.
The platform’s operational servers for Czech customers are located in the Czech Republic at the Algotech data centre. The 4cyber.cz and 4cybercity.cz websites use Active24 and WP Cloud hosting services.
Where a supplier acts as a processor, processing must be governed by an agreement under Article 28 GDPR. The engagement of sub-processors for customer data is governed by the data processing agreement and the customer’s applicable instructions.
Article 06Transfers outside the EU
When AI features are used, customer data is processed by a closed AI agent on an internal server and is not sent to public AI services.
The US parent company, 4Cyber Technologies Inc., has no access to Czech customers’ data.
The platform’s operational servers for Czech customers are in the Czech Republic. Any transfer of personal data to a third country as part of another specific service must meet the requirements of Chapter V GDPR and the applicable information obligations; the parent company’s location alone does not constitute such a transfer. Processing on the customer’s instructions is also governed by the data processing agreement.
Article 07Your data protection rights
Subject to the conditions set out in the GDPR, you may request access to, rectification or erasure of your data, restriction of processing and, where applicable, data portability. You may object to processing based on legitimate interests.
Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before consent was withdrawn. You may send a request to info@4cyber.cz. For newsletters, you may also use the unsubscribe link where included.
You have the right to lodge a complaint with the Czech Office for Personal Data Protection.
We handle requests under Article 12 GDPR. If we process data solely on the instructions of your employer or another organisation, contact that organisation as controller to exercise your rights; we provide it with the necessary assistance.
Article 08Personal data security
We protect data through technical and organisational measures appropriate to the nature and risks of processing. We use access controls and measures to protect systems and data. Access must be restricted to authorised individuals and to the extent necessary.
Article 09Automated decision-making and profiling
The platform enables the assessment of training, tests and phishing simulations. The customer determines the scope of processing of individual employees’ data and how results are used, according to the agreed features and settings; 4Cyber acts as processor when processing on its instructions.
If the customer uses individual behavioural or risk assessments, it must, as controller, also assess any profiling, the relevant legal basis and the information provided to affected individuals. Automated decision-making with legal or similarly significant effects must be assessed separately from the assessment of results itself.
AI outputs in GRC are proposals intended for the customer’s review and approval; they do not, on their own, confirm the organisation’s regulatory compliance or replace professional assessment.
Article 10Final provisions
This version of the policy was published on 4 October 2026. We update this information to reflect changes in actual processing. An amendment to this policy does not itself create a new legal basis for processing or replace consent where consent is required for specific processing.